CVE-2026-97873 | Legion of the Bouncy Castle Bouncy Castle for Java/Bouncy Castle for Java LTS prior 1.86/2.73.13 PBES1 javax.crypto.EncryptedPrivateKeyInfo.getKeySpec iteration
A vulnerability marked as problematic has been reported in Legion of the Bouncy Castle Bouncy Castle for Java and Bouncy Castle for Java LTS. This affects the function javax.crypto.EncryptedPrivateKeyInfo.getKeySpec of the component PBES1. The manipulation leads to excessive iteration.
This vulnerability is listed as CVE-2026-97873. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More